Problem Statement
What is the safest default firewall policy between network zones?
Explanation
Start closed, then open only what the business needs. This limits lateral movement and reduces blast radius when a host is compromised.
Code Solution
SolutionRead Only
Default: drop; Allow: tcp 443 to updates.example only
